The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,376
Mitigations17,075
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Use-your-Drive2.0-3.8.3
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
Just now
wpShopGermany IT-RECHT KANZLEI1.6-2.3
Unauthenticated RCE vulnerability
9
8 minutes ago
Filter Gallery<= 1.1.4
Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion vulnerability
8.1
11 minutes ago
Login with QR<= 1.0.0
Unauthenticated Authentication Bypass vulnerability
9.8
22 minutes ago
The Pressengine<= 1.0
Unauthenticated Authentication Bypass vulnerability
9.8
43 minutes ago
Private Feed Key<= 0.1
Unauthenticated Authentication Bypass vulnerability
9.8
46 minutes ago
King Addons for Elementor< 51.1.81
Contributor+ Stored XSS vulnerability
5.9
1 hour ago
King Addons for Elementor< 51.1.81
Contributor+ Private Post Content Disclosure vulnerability
2.7
1 hour ago
King Addons for Elementor51.1.56-51.1.80
Author+ Missing Authorization vulnerability
3.8
1 hour ago
MasterStudy LMS< 3.7.50
Instructor+ Order Status Manipulation vulnerability
3.8
1 hour ago
WordPress<= 7.1
Cross Site Scripting (XSS) vulnerability
7.1
2 hours ago
WP Recipe Maker<= 10.8.1
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
5.4
10 hours ago
Popup Maker<= 1.24.0
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
10 hours ago
@platejs/core< 53.3.11
NPM: @platejs/core HTML deserialization can trigger browser behavior during parsing
6.1
11 hours ago
devalue< 5.9.1
NPM: Svelte devalue: DoS via malformed input
5.3
11 hours ago
CSS & JavaScript Toolbox<= 12.0.6
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
5.9
11 hours ago
Photo Gallery by 10Web<= 1.8.44
Authenticated (Author+) SQL Injection vulnerability
6.5
11 hours ago
LatePoint<= 5.6.3
Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure vulnerability
4.3
12 hours ago
Filebird<= 6.5.6
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
5.4
12 hours ago
Kubio AI Page Builder<= 2.8.4
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
12 hours ago